Walkthrough

Anatomy of a Ransomware Attack

Updated

Ransomware does not begin with a splash screen. It begins with a file someone in the firm was supposed to open — an invoice, a closing binder, a shipping PDF, a staffing roster. Within minutes a process can start, a foothold can hold, and the shared folders that keep a CPA, law, manufacturing, or care team working can lock. This page walks the first hour in four beats so you can see where a tested backup and a desk that answers change the ending. It is a walkthrough, not a scoreboard. Manage IT NY is a New York cybersecurity and managed IT partner. Call (631) 557-0440 when you want the practice to stay open.

Stage 00

Beat 00

Minute 0: the file lands

A closing binder, an invoice PDF, a packing slip. Someone opens what looks like the day's work. That is the start — not a movie lock screen. On a tax-week workstation, a matter share, a plant office PC, or a nurses' station, the first minute is ordinary. The question is whether the firm notices before the file becomes a process.

Beat 01

A process starts and holds a foothold

If the file was hostile, a process can start and stay. It often looks like software doing a job. Logging, endpoint controls, and a person who will pick up the phone are what turn this minute from “we will see” into “we are containing.” A ticket queue that replies tomorrow is not a foothold response.

Beat 02

Shares lock as encryption spreads

The next move is not one laptop. It is the share everyone uses — client files, drawings, charts, billing. Encryption that reaches the file server is what closes a practice for a week. Segmentation, backups that actually restore, and stopping the spread matter more than the font on a ransom note.

Beat 03

Backups and a 24/7 desk change the ending

The ending is not guaranteed. Immutable backups, a tested restore, MFA, and a desk that answers at 2 a.m. are what keep the practice open. Manage IT NY works that problem so a professional firm is not waiting on a national queue while the share stays locked.

Questions firms ask

Straight answers before the share locks.

How fast can ransomware lock a professional firm?
Once a hostile file runs, a foothold can form in minutes and encryption can reach a shared drive the same day. Speed depends on controls, how flat the network is, and whether anyone is watching. The first hour is when a live desk still changes the ending.
If we have backups, are we safe?
Backups help only if they restore. They need to be reachable when the production share is not, tested, and protected from the same account that just got encrypted. A backup that has never been restored is a hope, not a plan — and carriers ask for the proof.
What should we do if someone opened a suspicious file?
Take the workstation off the network, do not pay or reboot into a cleanup you have not planned, and call a partner who will contain first. Manage IT NY at (631) 557-0440 is a desk that answers — not a form that promises a ticket number.

Ready to stay open — and ready for the carrier.

Book a call about backups that restore, MFA and logging a carrier will accept, and a desk that answers when a file should not have been opened. This is insurance readiness and operations — not a scare reel.